CVS Malformed Entry Modified and Unchanged Flag Insertion Heap Overflow Vulnerability

BID:10384

Info

CVS Malformed Entry Modified and Unchanged Flag Insertion Heap Overflow Vulnerability

Bugtraq ID: 10384
Class: Boundary Condition Error
CVE: CVE-2004-0396
Remote: Yes
Local: No
Published: May 19 2004 12:00AM
Updated: Jul 12 2009 05:16AM
Credit: This issue was discovered by Stefan Esser <[email protected]>.
Vulnerable: NetBSD NetBSD 1.6.2
NetBSD NetBSD 1.6.1
NetBSD NetBSD 1.6
NetBSD NetBSD Current
Gentoo Linux 1.4
CVS CVS 1.12.7
CVS CVS 1.12.5
+ OpenPKG OpenPKG 2.0
CVS CVS 1.12.2
+ OpenPKG OpenPKG Current
CVS CVS 1.12.1
+ OpenPKG OpenPKG 1.3
CVS CVS 1.11.15
CVS CVS 1.11.14
+ MandrakeSoft Corporate Server 2.1 x86_64
+ MandrakeSoft Corporate Server 2.1
+ Mandriva Linux Mandrake 10.0
+ Mandriva Linux Mandrake 9.2 amd64
+ Mandriva Linux Mandrake 9.2
+ Mandriva Linux Mandrake 9.1 ppc
+ Mandriva Linux Mandrake 9.1
CVS CVS 1.11.11
CVS CVS 1.11.10
CVS CVS 1.11.6
+ S.u.S.E. Linux Personal 9.0 x86_64
+ S.u.S.E. Linux Personal 9.0
CVS CVS 1.11.5
+ OpenPKG OpenPKG 1.2
+ S.u.S.E. Linux Personal 8.2
CVS CVS 1.11.4
CVS CVS 1.11.3
CVS CVS 1.11.2
+ Mandriva Linux Mandrake 9.0
+ Redhat Linux 8.0 i386
+ Redhat Linux 8.0
+ Slackware Linux 8.1
CVS CVS 1.11.1 p1
+ Debian Linux 3.0 sparc
+ Debian Linux 3.0 s/390
+ Debian Linux 3.0 ppc
+ Debian Linux 3.0 mipsel
+ Debian Linux 3.0 mips
+ Debian Linux 3.0 m68k
+ Debian Linux 3.0 ia-64
+ Debian Linux 3.0 ia-32
+ Debian Linux 3.0 hppa
+ Debian Linux 3.0 arm
+ Debian Linux 3.0 alpha
+ Debian Linux 3.0
+ OpenBSD OpenBSD 3.5
+ OpenBSD OpenBSD 3.4
+ OpenBSD OpenBSD 3.3
+ OpenBSD OpenBSD 3.2
+ OpenBSD OpenBSD 3.1
+ Redhat Linux 7.3 i386
+ Redhat Linux 7.3
+ Redhat Linux 7.2 ia64
+ Redhat Linux 7.2 i386
+ Redhat Linux 7.2 alpha
+ Redhat Linux 7.2
+ Redhat Linux 7.1 ia64
+ Redhat Linux 7.1 i386
+ Redhat Linux 7.1 alpha
+ Redhat Linux 7.1
+ Redhat Linux 7.0 sparc
+ Redhat Linux 7.0 i386
+ Redhat Linux 7.0 alpha
+ Redhat Linux 7.0
+ Redhat Linux 6.2 sparc
+ Redhat Linux 6.2 i386
+ Redhat Linux 6.2
+ SuSE Linux 8.1
+ SuSE Linux 8.0
+ Wirex Immunix OS 7.0
+ Wirex Immunix OS 7+
CVS CVS 1.11.1
+ Debian Linux 3.0 sparc
+ Debian Linux 3.0 s/390
+ Debian Linux 3.0 ppc
+ Debian Linux 3.0 mipsel
+ Debian Linux 3.0 mips
+ Debian Linux 3.0 m68k
+ Debian Linux 3.0 ia-64
+ Debian Linux 3.0 ia-32
+ Debian Linux 3.0 hppa
+ Debian Linux 3.0 arm
+ Debian Linux 3.0 alpha
+ Debian Linux 3.0
+ Mandriva Linux Mandrake 8.2 ppc
+ Mandriva Linux Mandrake 8.2
+ Mandriva Linux Mandrake 8.1 ia64
+ Mandriva Linux Mandrake 8.1
CVS CVS 1.11
+ Caldera OpenLinux Server 3.1.1
+ Caldera OpenLinux Server 3.1
+ Caldera OpenLinux Workstation 3.1.1
+ Caldera OpenLinux Workstation 3.1
+ Mandriva Linux Mandrake 8.0 ppc
+ Mandriva Linux Mandrake 8.0
CVS CVS 1.10.8
+ MandrakeSoft Single Network Firewall 7.2
+ Mandriva Linux Mandrake 7.2
CVS CVS 1.10.7
+ Debian Linux 2.2 sparc
+ Debian Linux 2.2 powerpc
+ Debian Linux 2.2 IA-32
+ Debian Linux 2.2 arm
+ Debian Linux 2.2 alpha
+ Debian Linux 2.2 68k
+ Debian Linux 2.2
Not Vulnerable: CVS CVS 1.12.8
CVS CVS 1.11.16

Discussion

CVS Malformed Entry Modified and Unchanged Flag Insertion Heap Overflow Vulnerability

CVS is prone to a remote heap overflow vulnerability. This issue presents itself during the handling of user-supplied input for entry lines with 'modified' and 'unchanged' flags. This vulnerability can allow an attacker to overflow a vulnerable buffer on the heap, possibly leading to arbitrary code execution.

CVS versions 1.11.15 and prior and CVS feature versions 1.12.7 and prior are prone to this issue.

**UPDATE: Symantec has confirmed that this vulnerability is being actively exploited in the wild. Administrators are urged to upgrade and block external access to potentially vulnerable servers, if possible.

Exploit / POC

CVS Malformed Entry Modified and Unchanged Flag Insertion Heap Overflow Vulnerability

CORE has developed a working commercial exploit for their IMPACT
product. This exploit is not otherwise publicly available or known
to be circulating in the wild.

Symantec has confirmed successful exploitation of this vulnerability in the wild. The following exploit code has been published:

Solution / Fix

CVS Malformed Entry Modified and Unchanged Flag Insertion Heap Overflow Vulnerability

Solution:
Debian has released an advisory DSA 505-1 to address this issue. Please see the referenced advisory for more information.

SuSE has released an advisory SuSE-SA:2004:013 to address this issue. Please see the referenced advisory for more information.

A FreeBSD advisory (FreeBSD-SA-04:10.cvs) is available that includes information about how to address this issue. Please see the attached advisory for further information.

OpenPKG has released advisory OpenPKG-SA-2004.022 that adresses this issue. Please see the attached advisory for further information.

Mandrake Linux has released advisory MDKSA-2004:048 and fixes dealing with this issue. Please see the referenced advisory for more information.

RedHat has released advisory FEDORA-2004-126 to provide fixes for Fedora Core 1. Please see the attached advisory for details on obtaining and applying fixes.

RedHat has released advisory FEDORA-2004-131 to provide fixes for Fedora Core 2. Please see the attached advisory for details on obtaining and applying fixes.

RedHat has released advisory RHSA-2004:190-14 to provide fixes for this issue. Please see the attached advisory in web references for details on obtaining and applying fixes.

A Slackware advisory (SSA:2004-140-01) is available that provides updates for this issue. Please see the attached advisory for further details.

Gentoo has released advisory GLSA 200405-12 to provide fixes for this issue. Please see the attached advisory for further details. It is recommended that affected users issue the following commands as superuser:
emerge sync
emerge -pv ">=dev-util/cvs-1.11.16"
emerge ">=dev-util/cvs-1.11.16"

OpenBSD has released patches to resolve this issue in versions 3.4 and 3.5. Please see the patch files themselves for instructions on applying them to your system. Please see the referenced announcement from Otto Moerbeek for more information.

CVS versions 1.11.16 and 1.12.8 have been released to address this issue.

Turbolinux has released advisory TLSA-2004-15 to provide fixes for this issue. Please see the attached advisory for further details.

Silicon Graphics has released advisory 20040508-01-U and fixes dealing with this and other issues for SGI ProPack 2.4. Please see the referenced advisory for more information.

NetBSD has released advisory 2004-008 addressing this issue. Please see the referenced advisory for further information:

Red Hat Fedora Legacy advisory FLSA-2004:1620 has been released dealing with this and other issues for Red Hat 7.3 and 9.0. Please see the referenced advisory for more information.

An Immunix Linux upgrade has been made available.


CVS CVS 1.10.7

CVS CVS 1.10.8

CVS CVS 1.11

CVS CVS 1.11.1 p1

CVS CVS 1.11.1

CVS CVS 1.11.10

CVS CVS 1.11.11

CVS CVS 1.11.14

CVS CVS 1.11.15

CVS CVS 1.11.2

CVS CVS 1.11.3

CVS CVS 1.11.4

CVS CVS 1.11.5

CVS CVS 1.11.6

CVS CVS 1.12.1

CVS CVS 1.12.2

CVS CVS 1.12.5

CVS CVS 1.12.7

References

CVS Malformed Entry Modified and Unchanged Flag Insertion Heap Overflow Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report